US2026067326A1PendingUtilityA1

Adaptive incident prioritization engine in a security management system

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Aug 28, 2024Filed: Nov 19, 2024Published: Mar 5, 2026
Est. expiryAug 28, 2044(~18.1 yrs left)· nominal 20-yr term from priority
H04L 63/1425G06F 40/30H04L 63/1441G06F 21/552
59
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods, systems, and computer storage media for providing security incident prioritization management using an adaptive incident prioritization engine of a security management system are described. The adaptive incident prioritization engine provides security incident prioritization based on an adaptive incident prioritization (AIP) framework built using a ranking algorithm. In particular, the adaptive incident prioritization framework employs a Best Matching 25 (BM25) algorithm and strategically and programmatically adapts the algorithm (e.g., an adaptive incident prioritization model) to rank security incidents based on a local security incident relevance metric (an adaptation of Term Frequency—TF—in BM25) and a global security incident rarity metric (an adaptation of Inverse Document Frequency—IDF—in BM25) associated with security incidents. A prioritization score for a security incident is calculated based on aggregating weighted frequencies of security incident ranking components (e.g., security incident metadata) within a security incident to determine an overall significance of the security incident.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computerized system comprising:
 one or more computer processors; and   computer memory storing computer-useable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations, the operations comprising:   accessing historical security data associated with a plurality security incidents of a computing environment;   identifying in the historical security data a plurality of security incident components associated with the plurality security incidents;   calculating global rarity metrics for the plurality of security incident components, wherein a global rarity metric is an adapted inverse document frequency that quantifies a rarity of a security incident component of the plurality of security incident components;   training an adaptive incident prioritization model based on the global rarity metrics of the plurality of security incident components; and   deploying the adaptive incident prioritization model.   
     
     
         2 . The system of  claim 1 , wherein a security incident component comprises security incident metadata that provides contextual information associated with a security incident, the security incident metadata includes an incident grade that identifies a severity of the security incident. 
     
     
         3 . The system of  claim 1 , wherein the adaptive incident prioritization model supports scoring security incidents based on corresponding local relevance metrics and global rarity metrics of the security incidents. 
     
     
         4 . The system of  claim 1 , wherein the adaptive incident prioritization model is operationalized with a training phase associated with a training pipeline and an inference phase associated with an inference pipeline. 
     
     
         5 . The system of  claim 1 , wherein the adaptive incident prioritization model supports generating security incident prioritization explanation data that provides a rationale associated with a plurality of security incident components and security incident prioritization score corresponding to a security incident. 
     
     
         6 . The system of  claim 1 , the operations further comprising:
 accessing a security incident associated with a computing environment;   accessing a plurality of security incident components of the security incident;   calculating local relevance metrics for the plurality of security components, wherein a local relevance metric is an adapted term frequency that quantifies a frequency of a security incident component of the plurality of security incident components;   accessing the global rarity metrics for the plurality of security incident components;   scoring the security incident based on the local relevance metrics and the global rarity metrics; and   ranking the security incident relative to a plurality of security incidents in the computing environment.   
     
     
         7 . The system of  claim 6 , the operations further comprising:
 accessing a security incident identifier associated with the security incident, a security incident prioritization score, and an adaptive incident prioritization explanation data, wherein the adaptive incident prioritization explanation data provides a rationale associated with a plurality security incident components for the security incident prioritization score;   causing display of the security incident identifier relative to a plurality of security incident identifiers on a security incident prioritization interface based on the security incident prioritization score; and   causing display of the adaptive incident prioritization explanation data associated with the security incident.   
     
     
         8 . The system of  claim 1 , the operations further comprising:
 communicating, from a security management client, a request for a security posture of a computing environment;   based on communicating the request, receiving a security posture visualization comprising a security incident identifier associated with a security incident, a security incident prioritization score, and an adaptive incident prioritization explanation data and   causing display of the security posture visualization.   
     
     
         9 . The system of  claim 8 , the operations further comprising:
 receiving an indication to execute a remediation action associated with the security incident identifier; and   communicating the indication to execute the remediation action to cause execution of the remediation action.   
     
     
         10 . A computer-implemented method, the method comprising:
 accessing a security incident associated with a computing environment;   accessing a plurality of security incident components of the security incident;   calculating local relevance metrics for the plurality of security components, wherein a local relevance metric is an adapted term frequency that quantifies a frequency of a security incident component of the plurality of security incident components;   accessing global rarity metrics for the plurality of security incident components, wherein a global rarity metric is an adapted inverse document frequency that quantifies a rarity of a security incident component of the plurality of security incident components;   scoring the security incident based on the local relevance metrics and the global rarity metrics; and   ranking the security incident relative to a plurality of security incidents in the computing environment.   
     
     
         11 . The method of  claim 10 , the operations further comprising:
 accessing customer feedback data, wherein the customer feedback data is received via a customer interface associated with a rating mechanism for rating rankings associated with security incidents; and   using the customer feedback data, generating adjusted feature weights associated with an adaptive incident prioritization engine;   based on the adjusted feature weights, generating an updated adaptive incident prioritization model; and   deploying the updated adaptive prioritization model.   
     
     
         12 . The method of  claim 10 , wherein scoring the security is based on an adaptive incident prioritization model that supports scoring security incidents based on corresponding local relevance metrics and global rarity metrics of the security incidents. 
     
     
         13 . The method of  claim 12 , wherein the adaptive incident prioritization model is operationalized with a training phase associated with a training pipeline and an inference phase associated with an inference pipeline. 
     
     
         14 . The method of  claim 12 , wherein the adaptive incident prioritization model supports generating security incident prioritization explanation data that provides a rationale associated with a plurality of security incident components and security incident prioritization score corresponding to the security incident. 
     
     
         15 . The method of  claim 10 , the method further comprising:
 based on ranking the plurality of security incidents, communicating the plurality of security incidents to cause display of the plurality of security incidents.   
     
     
         16 . One or more computer-storage media having computer-executable instructions embodied thereon that, when executed by a computing system having a processor and memory, cause the processor to perform operations, the operations comprising:
 accessing a security incident identifier associated with a security incident, a security incident prioritization score, and an adaptive incident prioritization explanation data, wherein the adaptive incident prioritization explanation data provides a rationale associated with a plurality security incident components for the security incident prioritization score;   causing display of the security incident identifier relative to a plurality of security incident identifiers on a security incident prioritization interface based on the security incident prioritization score; and   causing display of the adaptive incident prioritization explanation data associated with the security incident.   
     
     
         17 . The media of  claim 16 , wherein the security incident prioritization score is generated using an adaptive incident prioritization model that supports scoring security incidents based on corresponding local relevance metrics and global rarity metrics of the security incidents. 
     
     
         18 . The media of  claim 17 , wherein the adaptive incident prioritization model is operationalized with a training phase associated with a training pipeline and an inference phase associated with an inference pipeline. 
     
     
         19 . The media of  claim 16 , the operations further comprising:
 communicating a request for a security posture of a computing environment;   based on communicating the request, receiving a security posture visualization comprising the security incident identifier associated with the security incident, the security incident prioritization score, and the adaptive incident prioritization explanation data; and   causing display of the security posture visualization.   
     
     
         20 . The media of  claim 19 , the operations further comprising:
 receiving an indication to execute a remediation action associated with the security incident identifier; and   communicating the indication to execute the remediation action to cause execution of the remediation action.

Join the waitlist — get patent alerts

Track US2026067326A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.